Schedulign

Privacy Policy

Last updated September 30, 2026

The short version

  • Schedulign is a scheduling and booking service. We collect the information needed to run accounts, booking pages and bookings, and we use it for that.
  • We never sell personal information, never use it for advertising, and never use it — including Google user data — to train artificial intelligence or machine-learning models.
  • We use no analytics, advertising or tracking cookies, and load no third-party trackers.
  • If you connect Google Calendar, Schedulign reads only your list of calendars and the busy times on the calendars you choose, and writes only the events for your Schedulign bookings. It reads back only the time and status of those events, to notice when one was moved or deleted, and never reads the content of your events.
  • A client's booking information belongs to the business they book with. Schedulign stores and processes it on that business's behalf.
  • Health information a client gives a business is that business's to decide about. Schedulign processes it only for that business, never sells it, never shares it and never uses it for advertising. The separate Consumer Health Data Privacy Policy covers it in full.
  • You can export or delete your data, and ask us anything about it at admin@schedulign.com.

1. Who we are and what this policy covers

Schedulign LLC (“Schedulign”, “we”, “us”), 23312 77th Ave SE, Woodinville, WA 98072, United States, provides online scheduling at schedulign.com: booking pages, a dashboard for the people and businesses who sell their time, and the emails and calendar entries that go with each booking. Schedulign LLC is the company responsible for the personal information described in this policy, except where it acts on a business's behalf as described below. You can reach us at admin@schedulign.com.

This policy explains what personal information Schedulign collects, how it is used, who it is shared with, how long it is kept, and the choices and rights you have. It applies to everyone who uses Schedulign:

  • Clients — anyone who books, requests, reschedules or cancels a session on a Schedulign booking page, including the people they add as participants.
  • Hosts and businesses — anyone with a Schedulign account who offers sessions, whether working alone or as part of a team.
  • Team members — people invited to host sessions in someone else's workspace.
  • Subscribers — anyone who asks to be notified when a time opens up.
  • People on a waitlist — anyone who joins a business's waitlist for a time that is not open.
  • Signers — anyone who signs a business's document (such as a waiver) from a shared link.
  • Visitors — anyone browsing schedulign.com.

When a client books with a business, the business decides what it asks for and what it does with the answers. For that information Schedulign acts on the business's behalf, as its service provider, under our Terms of Service. The business's own privacy notice governs its own use of your information.

Consumer health data — information that identifies your physical or mental health status, which under Washington's My Health My Data Act, Nevada's consumer health data law and similar laws can include the fact that you booked a session with a health or wellness business — is described in our separate Consumer Health Data Privacy Policy at schedulign.com/consumer-health-data, with the rights those laws give you.

2. Information we collect

Information you give us

  • Account information: your name, email address and password (stored only as a one-way bcrypt hash), and optionally a phone number, a short bio and a profile photo.
  • Business information: your business's name, booking link, time zone, country, contact email, phone and WhatsApp number, logo, events, prices, policies, booking questions, documents (such as waivers), the consumer health data privacy policy you link or publish, availability, days off, client groups and a list of blocked clients with any note you add.
  • Contact book: the people you add by hand or import from a spreadsheet, whether or not they have booked — their name, email address, phone number and who referred them — with the labels, the columns of your own and the private notes you keep about them. You are responsible for having a lawful basis to hold them (see “For businesses” below).
  • Team information: the names and email addresses of the people you invite, and the permissions you give them.
  • Booking information: the client's name, email address, phone number when requested, the contact method they choose for the session, the names (and, where given, email addresses and phone numbers) of additional participants, answers to the business's booking questions, and — when a session location is chosen or entered — that address and any access details added (such as a gate code). Hosts may add private notes to a booking.
  • Document signatures: when you agree to a business's document, your typed name or agreement, your email address, the date, and the exact text of the document you agreed to.
  • Intake forms: when a business sends you its intake form, the answers you give (which can include health information), the name you type, your signature or confirmation, and when you sent it. Before the form is sent, it tells you what it collects, why, who receives it and how to withdraw, and asks for your consent. The answers are encrypted with AES-256-GCM before they are saved and are used only to provide that business's service to you. The business can read them, and each time someone at the business opens them, their name and the time are recorded. They are deleted when you withdraw your consent from the form's link (the answers sent through that link), or when the business deletes your details.
  • Openings alerts: your email address and the dates, times and period you chose to be notified about.
  • Waitlists: the time you are waiting for, the details you would book it with (your name, email address, phone number when requested, chosen contact, participants, answers, location and any document you signed), the price shown when you joined and how you chose to pay, when your place ends, and — if you save a card — its brand and last four digits. The card itself is kept by Stripe on the business's own Stripe account.
  • Support and problem reports: the message you write, the page you were on, your browser's user-agent string, the workspace you are signed in to (for hosts), your email address if you give one for a reply, and any screenshots you attach. Screenshots are sent to our support mailbox and are not stored in the Schedulign database.

Information collected automatically

  • Sign-in sessions: a sign-in cookie, your browser's user-agent string, and a one-way hash of your IP address, so you can review and end sessions.
  • Abuse protection: IP addresses (and one-way hashes of email addresses) in short-lived rate-limit records that stop repeated sign-in, booking, waitlist and sign-up attempts, and in server log lines for requests refused as suspicious.
  • Email delivery records: for each email Schedulign sends, the subject, a keyed hash of the recipient's address (never the address itself), the recipient's domain and whether delivery succeeded.
  • Activity log: a record of actions taken in the product (for example, a booking canceled or a setting changed), with the account that took them.
  • Error reports: technical details of errors, used to find and fix bugs (see Sentry under “How information is shared”).

Information from third parties

  • Google: if you sign in with Google or connect Google Calendar — described in full under “Google user data”.
  • Stripe: the status, amount and identifiers of payments, refunds and subscriptions, whether a business's Stripe account is ready to take payments, and the brand and last four digits of a card saved on a waitlist. Schedulign never receives full card numbers.

Information stored on your device

After you book, your browser can remember your name and email address for 90 days so the next booking form is filled in for you; a control on the form clears them. Your browser also remembers whether you prefer a 12- or 24-hour clock. This information stays on your device and is not sent to Schedulign until you book. See “Cookies and storage on your device”.

3. How we use information

  • To provide the service: showing booking pages and open times, taking bookings and requests, running the dashboard, creating calendar entries, and keeping each business's records of who booked, where, and what was paid or is owed.
  • To communicate about bookings and accounts: confirmations, reminders, changes, cancellations, receipts and refunds, time requests, document links, openings alerts you asked for, a business's mailing list you joined (the confirmation of your choices, with the link that changes them), emails about a waitlist place you joined, team invitations, password resets, email verification, and notices about changes to your account or workspace. These are transactional messages. Schedulign does not send marketing email.
  • To process payments through Stripe, for bookings and for Schedulign subscriptions.
  • To run waitlists: booking a time for you when it opens on a waitlist you joined, and charging a card you saved for it.
  • To keep Schedulign secure: preventing abuse and fraud, limiting repeated attempts, protecting accounts, and investigating problems.
  • To support you: answering problem reports and support requests.
  • To keep the service reliable: finding and fixing errors.
  • To comply with law and enforce our Terms of Service.

We do not use personal information for advertising, we do not sell it or rent it, we do not build advertising profiles, and we do not use it to train artificial intelligence or machine-learning models. Schedulign has no AI features that process your information.

5. Google user data

This section describes exactly how Schedulign accesses, uses, stores, shares, protects, retains and deletes data received from Google. Schedulign's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What Schedulign accesses

  • Sign in with Google (the openid, email and profile permissions): your name, email address and Google account identifier. Schedulign does not store or use your Google profile photo.

Google Calendar, only if you choose to connect it, with three permissions:

  • See the list of your calendars (calendar.calendarlist.readonly): the names and identifiers of your calendars, so you can choose which calendars block your times and which calendar receives your bookings.
  • See your free/busy information (calendar.freebusy): the start and end times of busy periods on the calendars you chose — never the titles, descriptions, locations, attendees or any other details of your events.
  • Create and manage events (calendar.events): used only to create the calendar event for each Schedulign booking, to update it when the booking is moved (including to another host of the event), paid or canceled (a canceled booking's event, and the old host's event when a session moves to another host, are kept, greyed and marked free, so you keep the record), and to add a Google Meet link when your event uses Google Meet, and to read back the time and status of those same events so you can be told when one was moved or deleted in Google Calendar (Google tells Schedulign only that the calendar changed, without any details). Schedulign never uses this permission to read, change or delete any other event in your calendar.

How Schedulign uses it

  • Your name, email address and Google account identifier: to create your account, sign you in and link Google sign-in to your existing account; and, when you host sessions in someone else's workspace and its owner or an admin lets you see clients' contact details, as the reply address on the emails your own actions on those sessions send their clients.
  • Your calendar list: to show you your calendars so you can make your choices.
  • Your busy times: to remove those times from your booking pages so you are never double-booked, and to check whether a time a client is waiting for on a waitlist has opened. Busy times are fetched at the moment open times are calculated, used in memory, and never stored.
  • Event access: to put your Schedulign bookings on your calendar, keep them current, and tell you when one was moved or deleted there.

Schedulign uses Google user data only to provide and improve these user-facing features. It is not used for any other purpose.

What Schedulign stores

  • Your Google account identifier and email address, as part of your Schedulign account.
  • The connection token Google issues when you connect your calendar, encrypted with AES-256-GCM before it is saved.
  • The identifiers of the calendars you chose, and whether your calendar events include your buffer times.
  • For each booking: the identifier of its calendar event and calendar, and the Google Meet link if one was created.

Schedulign does not store your busy times, the names of your calendars, or the content of any calendar event other than the ones it creates for your bookings.

Who receives Google user data

We never sell Google user data, never share it with advertisers, data brokers or information resellers, and never use it to train AI or machine-learning models. It is shared only in these ways:

  • Clients who book you: your name appears on your booking page and in booking emails. Your busy times are used only to hide those times, so clients see which times are open — never your calendar events or why a time is taken. A client may join a waitlist for a time that is not open, and is never told why it is not open. When a booking includes a Google Meet link, the link is sent to the client on that booking. When you host in someone else's workspace, an email that your own action on one of your sessions sends its client (a location you set, a cancellation with your note, a request you approve or decline, or a move you approve) shows your first name as the sender and, when the owner or an admin lets you see clients' contact details, carries your email address as a reply address, so the client's reply reaches you.
  • Your team, if you host sessions in someone else's workspace: the team owner and any admins the owner appoints can see your name and email address, whether you have a calendar connected (yes or no only), and the bookings made with you. When the owner, an admin or a permitted team member creates, moves, reassigns or cancels a booking you host, Schedulign writes that change into your calendar through your own connection. In your own workspace, the admins you appoint can see the same about you, and the same applies when one changes a booking you host. If the owner turns on “Also add my team members' bookings to my calendar”, a copy of each of your bookings — your first name, the event name, the client's name and the payment status — is written to the owner's own calendar through the owner's own connection. Nobody on a team can see your calendar names, your busy times or your calendar events, and nobody but you can connect, disconnect or change your calendar connection. See “Team workspaces”.
  • Your own Google Calendar: the events Schedulign creates for you — the event name, the client's name, the payment status, and the client's email address and phone number (left out for a team member who is not permitted to see client contacts) — are written into your calendar. Anyone you share that calendar with in Google can see them, as with any event. Schedulign does not add clients as attendees, so Google does not email them invitations.
  • Service providers who run Schedulign for us, only to provide the service and under confidentiality and data-protection obligations: Railway (hosting and database, where your Google account identifier, email address, chosen calendars and encrypted connection token are stored), GitHub (encrypted nightly database backups), Resend (delivering the booking emails that carry your name and Meet links) and Sentry (error monitoring, with email addresses and sign-in tokens removed before a report leaves our servers).
  • Schedulign personnel, only as described under “Human access” below.
  • Legal and safety: when required by law, a court order or other valid legal process, or when necessary to protect the safety, rights or property of our users, the public or Schedulign.
  • Business transfer: if Schedulign is merged, acquired or sells its assets, to the successor, who must continue to protect your data under this policy, and only with prior notice to you.

Human access

Schedulign personnel do not read Google user data, except: with your explicit permission (for example, when you ask for help with your calendar connection); when necessary for security purposes, such as investigating abuse; to comply with applicable law; or in aggregated, anonymized form for internal operations. The staff support console shows only whether a calendar is connected — never connection tokens, calendar names, busy times or calendar events.

How Google user data is protected

Connection tokens are encrypted at rest with AES-256-GCM and can be re-encrypted under a new key. All traffic between you, Schedulign and Google is encrypted in transit with TLS. Schedulign never shows a connection token to anyone, including our staff and your team. See “Security” for the full list.

Retention and deletion of Google user data

  • Busy times are never retained. They are discarded as soon as open times are calculated.
  • Disconnecting Google Calendar (Settings → Scheduling → Calendars) revokes Schedulign's access at Google and deletes the stored connection token and your calendar choices at once. Events Schedulign already created stay in your calendar, because they belong to you; you can delete them in Google Calendar.
  • Deleting your account deletes your Google account identifier, email address, connection token and calendar choices.
  • You can also remove Schedulign's access at any time from your Google Account at myaccount.google.com/permissions.
  • Deleted data leaves our encrypted backups within 30 days.
  • To ask for deletion of any Google user data, email admin@schedulign.com.

Limited Use

Schedulign's use of Google user data is limited to providing and improving the user-facing features described above. Schedulign does not transfer Google user data to others except as needed to provide or improve those features, for security purposes, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to you. Schedulign does not use or transfer Google user data for serving advertisements, including personalized, retargeted or interest-based advertising; does not sell it; does not transfer it to data brokers or information resellers; and does not use it to determine credit-worthiness or for lending purposes.

AI and machine learning

Schedulign does not use data obtained through Google Workspace APIs or any other Google API to develop, improve or train generalized or non-personalized artificial intelligence or machine-learning models, and does not share it with anyone who does.

6. How information is shared

We never sell personal information and never share it for cross-context behavioral advertising. Information is shared only as follows.

Between the people on a booking

  • When you book, the business you book with receives your booking information: the host of your session and, depending on the business's settings and permissions, its owner, its admins and other team members (see “Team workspaces”).
  • Contact details you choose to share with the host for the session reach the host, whichever team member hosts it, and the owner and admins.
  • When you join a waitlist, the business receives your place and the details you joined with. Its owner and admins can see the place; other team members cannot until the time is booked for you, when it is shared like any booking.
  • Clients see a business's name, logo, booking link, contact details, hosts' names and photos, events, prices, policies and open times. On an email a team member's own action sent about a session they host (a location they set, a cancellation with their note, a request they answered or a move they approved), the client also sees that member's first name as the sender and, when the owner or an admin lets the member see clients' contact details, their email address as a reply address.
  • Participants you add to a booking are not emailed by Schedulign.

Service providers

These companies process personal information for Schedulign, only to provide the service, and under confidentiality and data-protection obligations:

  • Railway — application hosting, the database (including uploaded logos and photos), server logs, and an encrypted copy of our backups. United States.
  • GitHub — runs our scheduled jobs (reminders, retention clean-up) and holds encrypted nightly database backups for 30 days.
  • Stripe — payments and billing. For a booking paid online, the charge is made directly on the business's own Stripe account; Stripe receives the client's email address, the event name, the host's name (when one is assigned), the session's date, time and length, the number of participants, the amount, any tax and tip, and booking identifiers. You enter your card details on Stripe's own page. When you choose to save a card for a waitlist place, Stripe receives your name and email address, to keep the card on the business's own Stripe account, and a charge to that card carries the amount and booking identifiers. For businesses, Stripe receives the owner's email address and business name to create a Stripe account or a Schedulign subscription, and collects identity and bank details directly during Stripe's own onboarding. Stripe's privacy policy applies to what Stripe collects.
  • Resend — email delivery. Emails carry what the message is about: names, session times, locations and access details, amounts, payment instructions, policy text, and the links to manage a booking.
  • Sentry — error monitoring. Configured with no session replay, no performance tracing, no cookies, no IP addresses and no request bodies, so a report never carries what a form sent; email addresses, sign-in tokens in web addresses and query strings are removed before a report is sent. A report may still contain other details of the failure, such as a name in an error message.
  • Google — sign-in and calendar, when you choose them (see “Google user data”), and Google Workspace, which hosts our support mailbox, where problem reports and support emails arrive.

Images a business links to

A business may set its logo or a host photo to an image hosted on another website. When you view that page, your browser loads the image from that website, which can see your IP address and browser details, as with any image on the web.

Legal, safety and business transfers

We may disclose information when required by law, a court order or other valid legal process; to protect the safety, rights or property of our users, the public or Schedulign; to investigate fraud or abuse; or to enforce our Terms. If Schedulign is involved in a merger, acquisition or sale of assets, information may be transferred to the successor, who must honor this policy, and we will notify you before it becomes subject to a different policy.

With your consent

We share information in other ways only when you ask us to or agree to it.

7. Team workspaces: what owners, admins and members can see

Every person on Schedulign owns their own account. A team is a workspace owned by one person (the owner) in which other people (members) host sessions. What a member can see and do in the workspace is set by a list of permissions, each of which starts off. The owner can make a member an admin, who helps run the workspace.

What a team owner can see about each member

  • Profile: name, email address, phone number, bio and photo, role, permissions, whether they can be booked, and whether their invitation is pending, accepted or ended.
  • Calendar: whether the member has a calendar connected — yes or no only.
  • Hours: the member's weekly hours for the team, their date-specific hours and days off for the team, and a notice when the member limits their team hours to one of their own schedules (not the schedule's contents).
  • Bookings: every booking in the workspace, including every booking the member hosts, in full — the client's name, email address, phone number and chosen contact, answers to booking questions, participants, payments, refunds, tax and tips, the Stripe payment identifier, the full text of any signed document and the name it was signed with, location and access details, the Google Meet link, notes, and the booking's history of changes.
  • Reports: per-host figures such as sessions delivered, revenue, amounts outstanding, cancellations, no-shows, upcoming sessions, events hosted and first-time clients.
  • Exports: a download of the workspace's data, including member records (name, email address, phone number, bio, photo, permissions and dates) — never passwords, sign-in tokens or calendar tokens.
  • Emails: the booking notices on members' sessions (bookings, cancellations, moves, requests, locations set and each session someone other than the owner marks paid offline), each as it happens, in one daily summary, or both, as the owner chooses (each as it happens by default; the owner can also turn them off); time requests a member is not permitted to answer; cancellations of sessions paid online; changes members make to their own hours or to events they host; and changes an admin makes to the business's settings or to who can be booked.
  • Invitations: when inviting an email address, whether it already has a Schedulign account.

What a team owner can do

  • Edit a member's team profile, switch whether they can be booked, change their permissions, set their team hours and days off, resend an invitation or remove a member.
  • Create, move, approve, cancel, refund and mark paid the bookings on a member's sessions, and delete a client's details from a past or canceled booking. Changes to a member's bookings are written into the member's connected calendar through the member's own connection.
  • Reassign a session whose client booked any available host to another host of the event, who then sees it as its host, with the notes written since. The member who hosted it before no longer sees it in Schedulign (the entry already on their calendar stays, greyed and marked free, with the client's contact details and links taken off), and the client is emailed the new host's name.
  • Turn on a copy of members' bookings in the owner's own calendar (the member's first name, the event name, the client's name and the payment status), marked as free time.

What a team owner can never see or do

  • See, set or reset a member's password.
  • Connect, disconnect or change a member's calendar connection, or see a member's calendar names, busy times or calendar events.
  • See a member's own workspace or their other workspaces. A member's bookings elsewhere and their calendar's busy times only hide times, and the team never sees why a time is hidden or why a member is not free to take a session.
  • See a member's sign-in activity or devices, or sign in as the member.

What an admin can see and do

  • An admin can see and do what the owner can, as listed above: every booking in full, the workspace's contacts with their labels and notes, its waitlist, members' profiles, permissions and team hours, reports and the settings of the business.
  • An admin can download the bookings, contacts and events lists, which include clients' names, email addresses and phone numbers.
  • An admin cannot change the plan or billing, connect or disconnect the workspace's Stripe account, download the workspace's full data export, delete the workspace, make or remove admins, or change the owner's own profile, sign-in, calendar, calendar copy, saved schedules or team email settings.
  • The limits under “What a team owner can never see or do” apply to admins too. Notices meant for the owner, such as copies of booking notices, keep going to the owner.

What a member can see

  • Only the sessions they host: the client's name, participants' names, price and payment status, refunds, the name of any signed document and the name it was signed with, the location and access details, and the notes written on those sessions while they host them, including notes by the owner and admins.
  • Only with a permission from the owner or an admin: clients' email addresses and phone numbers (a phone-call session always shows the number to call), answers to booking questions, the contact the client chose for the session, and the intake forms of the clients of their own sessions. The same limits apply to the member's emails and calendar entries; a client's reply to an email the member's own action sent reaches the member only if the member had the contact-details permission when that email was sent.
  • About the workspace: its name, link and contact details, the names of its saved schedules and documents, and the names and sizes of its client groups.
  • On an event they share with other hosts: the first names of the other hosts who have joined it.
  • A member who is not an admin cannot see other members' details (only those first names), the workspace's client list or waitlist, reports, exports, settings (including how Any available picks a host), Stripe payment identifiers or the full text of signed documents.

When a member leaves or is removed

The member's access to the workspace ends at once and both sides are notified. The member's record and the history of bookings they hosted stay with the workspace as its records. Events they host alone are taken off the booking page, and they are taken off the host list of events they share, which keep their other hosts. Notices about their sessions go to the owner, and Schedulign stops writing to their calendar; entries already in their calendar stay there. Their own account, their calendar connection and their other workspaces are not affected. Clients who reply to an email the member's own action sent earlier still reach the member's email address when that email gave it as a reply address.

When a workspace is deleted

The workspace goes offline immediately and its bookings, events, members' records, images and settings are permanently erased within 30 days. Each person's own account survives; an account left with no workspace is deleted shortly afterwards.

8. Access by Schedulign personnel

A small number of authorized Schedulign personnel can use a separate staff console, with its own sign-in, a 12-hour session limit and lockout after repeated failed attempts. It is used only to support users, keep the service secure and operate it. Personnel cannot sign in as you or open your workspace.

  • What the console shows: counts across the service; for each workspace, its members' names, email addresses, roles and join dates, whether the owner signed up with Google and has a calendar connected, its events, its most recent bookings with client details masked, and recent entries from its activity log (which can include names and email addresses).
  • When looking up an email address to answer a support request: the account's name and creation date, whether the email is confirmed, how the person signs in, whether a calendar is connected, when the account was last active, its workspaces and invitations, bookings made with that email address, email delivery records, and problem reports.
  • What personnel can do: resend a booking confirmation, send a password-reset link, resend an email-confirmation link, and mark a problem report resolved. Each action is recorded.
  • What the console never shows: passwords, sign-in or connection tokens, calendar names, busy times or calendar events.

9. Cookies and storage on your device

Schedulign uses only the cookies it needs to work. There are no analytics, advertising or third-party tracking cookies, and fonts are served from schedulign.com rather than a third party. Booking does not require an account.

  • Sign-in: keeps you signed in to your dashboard; up to 14 days.
  • Sign-in security: two cookies that protect Google sign-in and calendar connection from forgery; 10 minutes.
  • Google sign-up: carries your name and email address from Google to the sign-up form; 15 minutes.
  • Event access codes: one per private event, remembering that you entered the business's access code; 30 days.
  • Staff console: two cookies used only by Schedulign personnel; 12 hours and 30 minutes.
  • On your device, not cookies: your name and email address from your last booking, kept for 90 days to fill in the next form (with a control to clear them); your 12- or 24-hour clock preference; which view of Bookings you last chose, a list or a week; on a business's page with updates, which reactions you gave and when you last opened them; and, for the length of a browser session, whether you have seen the demo tour or a team invitation.

Because Schedulign does not track you across sites or sell or share personal information for advertising, there is nothing to opt out of; Schedulign treats Global Privacy Control and Do Not Track signals as a request not to sell or share, which it already honors for everyone.

10. How long we keep information

  • Accounts and workspaces: for as long as they exist.
  • Bookings: for the life of the business's workspace, as its operating history, unless the business deletes a client's details sooner.
  • Contact book: for the life of the business's workspace, unless the business deletes the contact or the client's details sooner.
  • Intake forms: for the life of the business's workspace, unless you withdraw your consent from the form's link, or the business deletes the client's details, sooner — either deletes them and the record of who opened them.
  • A deleted workspace: offline immediately and permanently erased within 30 days; rolling backups age out within 30 days after that. An account left with no workspace is deleted shortly afterwards.
  • Openings alerts: until you unsubscribe or the period you chose ends; entries are deleted 30 days after you unsubscribe.
  • Waitlist places: until the time is booked for you, you leave or your place ends, and then 30 days more before the place is deleted. A saved card, and the name and email address Stripe received to keep it, are removed from the business's Stripe account once the time is booked for you or your place ends.
  • Mailing-list choices: until you leave the list from the link in any of its emails, or the business deletes your contact.
  • Sign-in sessions: end after 14 days or when you sign out; their records (browser and hashed IP address) are deleted 30 days later.
  • Rate-limit records, including IP addresses: 1 day.
  • Email delivery records: 90 days.
  • The list behind a team owner's daily summary (which booking changed, how, and which team member acted; never a client's details): 7 days.
  • Payment notification records from Stripe: 90 days.
  • Problem reports: 180 days in the database; the email copy in our support mailbox for as long as needed to resolve the request.
  • Activity log: 1 year. Personal details are removed from it when a workspace, or a booking's client details, are deleted.
  • Server logs and error reports: short periods set by our hosting and error-monitoring providers.
  • Records of Schedulign staff actions: kept as a security record.
  • Backups: encrypted, rolling, and deleted after 30 days, so deleted data leaves the backups within 30 days of deletion.

We may keep information longer where the law requires it, or to resolve disputes, prevent fraud or abuse, or enforce our Terms.

11. Security

  • All traffic is encrypted in transit with TLS, and browsers are told to use only secure connections.
  • Data is encrypted at rest by our hosting provider; backups are separately encrypted with AES-256.
  • Passwords are stored only as bcrypt hashes; Schedulign refuses common passwords.
  • Google Calendar connection tokens are encrypted with AES-256-GCM. Password-reset, email-verification and invitation tokens are stored only as one-way hashes, and the links clients use to change a booking are signed and expire.
  • Intake form answers are encrypted with AES-256-GCM before they are saved, and each opening of them is recorded.
  • Card numbers never touch Schedulign's servers.
  • Sign-in, sign-up, booking and other sensitive actions are rate-limited. Sessions can be ended at any time (Settings → Profile → Sign out everywhere), and changing your password ends your other sessions.
  • Access to production systems and the staff console is limited to authorized personnel, and staff actions are recorded.
  • Server logs are written with passwords, tokens, secrets and email addresses removed.

No system is perfectly secure. If a breach affects your personal information, we will notify affected users and the business involved promptly, as the law requires.

12. Your rights and choices

Wherever you live, you can ask to access, correct, export or delete the personal information Schedulign holds about you, and to object to or restrict how it is used. Schedulign does not discriminate against anyone for exercising these rights.

  • Businesses: download everything from Settings → Danger zone → Your data, and delete your workspace there too. Correct your details in Settings.
  • Clients: ask the business you booked with — it can correct your details or delete them from a past or canceled booking — or email us and we will take care of it. You can find your bookings and download them from the find-my-bookings page, or ask us for a copy.
  • Openings alerts: every alert email has a one-click unsubscribe link.
  • Waitlists: every email about a place you still hold links to that place's page, where you can leave the waitlist or remove a saved card; the find-my-bookings page lists your places, and its download includes them.
  • Mailing lists: the confirmation email carries the link that changes your choices or leaves the list; the business can also remove you from its Contacts.
  • Intake forms: withdraw your consent at any time from the form's link, which deletes the answers you sent through it and tells the business.
  • Health information: Washington, Nevada and similar laws give you further rights over consumer health data — to confirm, see, correct and delete it, to withdraw consent, and to appeal a refusal. The Consumer Health Data Privacy Policy explains how to use them.
  • Google: disconnect your calendar in Settings → Scheduling → Calendars, or remove Schedulign's access from your Google Account.
  • Consent: withdraw it at any time; this does not affect what was done before.

Send requests to admin@schedulign.com. We verify requests by confirming control of the email address involved, may accept requests from an authorized agent with your signed permission, and respond within one month. When a request concerns information a business holds about its clients, we may pass it to that business, which decides it, and help the business carry it out. If you are in the EEA, the UK or Switzerland, you may also lodge a complaint with your local data protection authority.

13. Additional information for U.S. state residents

This section is for residents of California and other U.S. states with comprehensive privacy laws. In the past 12 months Schedulign has collected the following categories of personal information, from you, from the business you booked with, from your device, and from Google and Stripe as described above:

  • Identifiers: name, email address, phone number, account identifiers, IP address (hashed or kept for one day).
  • Customer records: address and access details for a session, payment status and amounts, and the brand and last four digits of a card saved on a waitlist.
  • Commercial information: bookings, waitlist places, subscriptions and payments.
  • Internet or network activity: browser type, and records of actions in the product.
  • Professional information: business name and the services offered.
  • Sensitive personal information: account sign-in credentials (email address and password), used only to sign you in; and health information a client gives on a business's intake form, used only to provide that business's service to the client.

Each category is used for the purposes in “How we use information” and disclosed for business purposes only to the service providers and people listed in “How information is shared”. Schedulign has not sold or shared personal information for cross-context behavioral advertising, does not use sensitive personal information to infer characteristics about anyone, and has no actual knowledge of selling or sharing the information of anyone under 16. You have the rights described in “Your rights and choices”, including to know, correct, delete and opt out, and the right not to be discriminated against for using them.

14. International transfers

Schedulign is operated from, and its data is stored in, the United States. If you use Schedulign from elsewhere, your information is transferred to and processed in the United States and in the other countries where our service providers operate, where data protection laws may differ from those of your country. We protect it as this policy describes wherever it is processed.

15. Children

Schedulign accounts are for adults, and the service is not directed at children under 13. A booking may list a minor as a session participant (a parent booking a child's session) — that is the parent's information, entered by the parent, handled like the rest of the booking. If you believe a child has given us personal information, contact us and we will delete it.

16. For businesses: your clients' information

When you take bookings on Schedulign, you decide what to ask your clients and what to do with their answers, and you are responsible for having a lawful basis for it, telling your clients how you use their information, and answering their requests. The same applies to the people you add to your contact book or import from a spreadsheet, whether or not they have booked. Schedulign stores and processes your clients' information on your behalf, only to run your bookings, as set out in our Terms of Service, and gives you the tools to export it and to delete a client's details.

If your clients' information includes consumer health data — and under Washington's, Nevada's and similar laws a booking with any health or wellness business can — Schedulign is your processor under the Terms' processor terms, and you can link your own Consumer Health Data Privacy Policy, or publish one from Schedulign's template, in Settings → Forms & waivers; your booking pages, intake forms and waivers then link it.

17. Changes to this policy

When this policy changes, the updated version will be posted here with a new date. If a change materially affects how your personal information is used, we will also tell account holders by email or in the product before it takes effect.

18. Contact

Privacy questions, requests and complaints: admin@schedulign.com, or by mail to Schedulign LLC, 23312 77th Ave SE, Woodinville, WA 98072, United States.

See also the Terms of Service and the Consumer Health Data Privacy Policy.